Impact
Improper privilege management in the Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows allows a low‑privileged local user to obtain SYSTEM privileges on the host. The flaw, identified as CWE‑269, permits the attacker to elevate privileges to full system rights. This can potentially enable full control over the affected system, including executing arbitrary code, installing software, or exfiltrating data.
Affected Systems
The vulnerability afflicts Citrix Secure Access Client for Windows versions prior to 26.6.1.20 and Citrix Endpoint Analysis Client for Windows versions prior to 26.5.1.7. Systems running the impacted Windows client software are susceptible, while later releases contain the fix.
Risk and Exploitability
The CVSS score of 8.5 classifies the issue as high severity. The EPSS score of less than 1% indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local: a user who can run the client application with standard privileges can trigger the elevation. This local nature limits exposure to physical or remote users who can access the machine, but once compromised the attacker gains full system rights.
OpenCVE Enrichment